# fail2ban vs CSF in 2026: Which Firewall for a Hosting Server?

Source: https://srvscripts.com/guides/fail2ban-vs-csf/
Updated: 2026-10-07
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** CSF is a complete firewall (it opens and closes ports) plus a login-failure daemon (lfd) with process tracking and cPanel/DirectAdmin screens; fail2ban only reads logs and bans IPs, so it needs a firewall such as firewalld or nftables under it. On cPanel and DirectAdmin, CSF is still the easier fit in 2026 through the panel-maintained forks (cPanel’s `cpanel-csf` and DirectAdmin’s own build). On Plesk and on servers without a panel, use fail2ban with firewalld or nftables. Do not run both as separate firewalls on one server.

We ran the version and resource checks on this page on our lab servers on 7 October 2026: CSF v15.12 (DirectAdmin build) on AlmaLinux 9.8 with DirectAdmin 1.712, and fail2ban 1.0.2 on Debian 12 with FreePBX. Feature claims are checked against the CSF readme shipped with that build, the fail2ban source code and the vendor documentation linked below.

## What CSF and fail2ban are in 2026

### CSF: firewall plus lfd, now maintained as forks

ConfigServer Security & Firewall (CSF) writes the server’s packet-filter rules itself (allowed ports, allow and deny lists, flood limits) and runs **lfd**, a daemon that watches logs and processes and blocks IPs through CSF. Its original developer, Way to the Web Ltd (ConfigServer), closed on 31 August 2025 and released CSF under the GPLv3. cPanel’s [support article](https://support.cpanel.net/hc/en-us/articles/37654028162071) says cPanel provides its own fork from 25 February 2026, installed as `cpanel-csf`, and that the fork gets critical security and stability fixes only, with no new features. DirectAdmin ships its own build: on our DirectAdmin lab, `csf -v` prints `csf: v15.12 (DirectAdmin)`, and its changelog shows recent fixes such as a CVE patch in 15.12 and updated Dovecot and OpenSSH log patterns.

Other community forks exist for servers without these panels. Our [CSF fork 2026 comparison](/guides/csf-fork-2026-after-configserver/) covers them; the short version is to run the fork your panel vendor ships.

### fail2ban: a log-based ban daemon

fail2ban is a Python daemon that tails log files (or the systemd journal), matches lines against filters, and when an IP fails too often within a time window it runs a ban action against a firewall. It does not manage ports or default policy; that stays with firewalld, nftables, iptables or another firewall. It is actively developed: the [upstream repository](https://github.com/fail2ban/fail2ban) has a 1.1.1 release tag and commits from September 2026, and [EPEL](https://packages.fedoraproject.org/pkgs/fail2ban/fail2ban/) packages 1.1.0 for EL9 and EL10.

## Feature comparison

The CSF column describes the cPanel and DirectAdmin forks, which share the same configuration options. The fail2ban column describes upstream fail2ban with its bundled filters and actions.

| Feature | CSF + lfd | fail2ban |
| --- | --- | --- |
| Port control (open/close ports, default deny) | Yes: TCP_IN, TCP_OUT, IPv6 in csf.conf | No; use firewalld or nftables for this |
| Login failure detection | Built in for SSH, FTP, SMTP AUTH, POP3, IMAP, panel logins, ModSecurity, .htaccess and more (LF_* options) | Yes, through filters: sshd, dovecot, exim, postfix, pure-ftpd, proftpd, roundcube-auth, directadmin, mysqld-auth and many more; custom filters are regular expressions |
| Repeat offenders | Permanent block after repeated temp blocks (LF_PERMBLOCK) | recidive jail |
| Process tracking | Yes: user process count and memory limits (PT_USERPROC, PT_USERMEM) with alerts or kills | No |
| Directory and file watching | Yes: LF_DIRWATCH for suspicious files in /tmp and similar | No |
| Connection and flood limits | Yes: CONNLIMIT, PORTFLOOD, SYNFLOOD, CT_LIMIT | No (it reacts to log lines, not connection counts) |
| Country blocking | Yes: CC_DENY, CC_ALLOW | No |
| Outbound SMTP restriction | Yes: SMTP_BLOCK | No |
| Panel UI | WHM, DirectAdmin and Webmin screens; InterWorx and CWP integrations listed in the readme | No CSF-style UI; Plesk has its own fail2ban screen |
| Firewall backend | Writes iptables rules; on AlmaLinux 9 these go through the iptables-nft layer (our lab: iptables v1.8.10 (nf_tables)), with ipset for large lists | Native actions for nftables (nftables-multiport, nftables-allports), firewalld (firewallcmd-rich-rules, firewallcmd-ipset), iptables, and even CSF (csf) |
| Configuration style | One large csf.conf plus allow/deny/ignore files | Jails in jail.local / jail.d/, filters and actions as separate files |
| Maintenance | Panel forks: fixes only (cPanel) or panel-driven (DirectAdmin) | Active upstream project |

### nftables and AlmaLinux 10

This is the main long-term difference. Red Hat marked `iptables-nft` and `ipset` as deprecated in RHEL 9, and the [RHEL 10 release notes](https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/10.0_release_notes/deprecated-features) say `ipset` is unmaintained and planned for removal in a future major release, recommending nftables sets instead. CSF still drives iptables commands, so it depends on that compatibility layer; before you deploy it on AlmaLinux 10, test your exact build (see [CSF on AlmaLinux 10: nftables and ipset problems](/guides/csf-almalinux-10-nftables-ipset/)). fail2ban already talks to nftables and firewalld natively, so it does not have this dependency.

## Resource use

Neither tool is heavy. A snapshot from our labs on 7 October 2026 (resident memory from `ps`):

| Server | Process | Memory (RSS) | Notes |
| --- | --- | --- | --- |
| DirectAdmin 1.712, AlmaLinux 9.8, 3 domains | lfd - sleeping (CSF v15.12) | about 35 MB | Default DirectAdmin CSF config: SSH, FTP, mail and panel login tracking, process tracking, LF_DIRWATCH = 300 |
| FreePBX 17, Debian 12 | fail2ban-server 1.0.2 | about 33 MB | 8 jails, backend = auto |

One server each is not a benchmark, but the point holds: memory is similar. CPU is where they differ under load. lfd’s cost grows with the extra checks you enable (process tracking, directory watching, connection tracking), and fail2ban’s grows with log volume and the number of regular expressions per line. On a busy mail server, keep fail2ban on the systemd journal or small dedicated logs, and on CSF turn off checks you do not use. To check your own server:

```
ps -eo pid,rss,etime,args | grep -E 'lfd|fail2ban-server' | grep -v grep
fail2ban-client status
csf -v
```

## Panel compatibility: cPanel, DirectAdmin, Plesk

| Panel | CSF | fail2ban |
| --- | --- | --- |
| cPanel & WHM | Supported fork cpanel-csf (yum install cpanel-csf or apt install cpanel-csf); WHM plugin; security and stability fixes only | Installable; cPanel’s install article notes that cPHulk does a similar job. No WHM screen |
| DirectAdmin | DirectAdmin’s own build via CustomBuild (csf=yes in options.conf on our lab); plugin in the DirectAdmin UI | Works; upstream ships a directadmin filter for panel logins |
| Plesk | Not listed in the CSF readme’s panel integrations | Built in as “IP Address Banning (Fail2Ban)” in Tools & Settings, with 13 preconfigured jails (Plesk docs) |
| No panel | Generic install of a community fork | Distribution packages; pair with firewalld or nftables |

**Watch the EPEL package on cPanel and DirectAdmin.** On EL9, the `fail2ban` meta-package from EPEL pulls in `fail2ban-firewalld`, which requires firewalld and sets `banaction = firewallcmd-rich-rules`. Running firewalld next to CSF gives you two firewalls fighting over the same rules. If you want fail2ban on a CSF server, install `fail2ban-server` only and use the `csf` action (next section).

Imunify360 is a third option on cPanel and DirectAdmin: it can replace CSF as the firewall and handles brute-force blocking itself (see [Imunify360 without CSF](/guides/imunify360-without-csf/)).

## Can you run fail2ban and CSF together?

Yes, if fail2ban only feeds CSF instead of writing its own rules. fail2ban ships an action, `action.d/csf.conf`, that bans with `csf --deny <ip>` and unbans with `csf --denyrm <ip>`. Its own header warns that CSF has been seen removing bans created by other iptables-based actions, and says not to mix CSF with other iptables actions. So set it for every jail:

```
# /etc/fail2ban/jail.local
[DEFAULT]
banaction = csf
banaction_allports = csf

[wordpress-login]
enabled  = true
filter   = wordpress-login
logpath  = /var/log/apache2/domlogs/*.log
maxretry = 10
findtime = 10m
bantime  = 1h
```

The `wordpress-login` filter is an example name: fail2ban does not ship one, so you write the filter yourself (our [fail2ban regex generator](/tools/ai-fail2ban-regex-generator/) can draft it from real log lines). Check the log path for your panel and web server. This pattern is useful when you want a ban rule CSF’s lfd does not have, while keeping CSF as the only firewall.

## Which one to use: recommendation per scenario

| Scenario | Recommendation | Why |
| --- | --- | --- |
| cPanel shared hosting | CSF (cpanel-csf) plus cPHulk, or Imunify360 instead of CSF | WHM integration, process tracking and per-service login blocking out of the box; cPanel maintains the fork |
| DirectAdmin | DirectAdmin’s CSF build | Installed and updated through CustomBuild with DirectAdmin-specific log patterns |
| Plesk | Plesk’s built-in fail2ban | Already integrated with Plesk’s logs and UI; CSF does not list Plesk support |
| VPS without a panel (web, API, small mail) | firewalld or nftables + fail2ban | Native nftables support, active upstream, small and easy to audit |
| New AlmaLinux 10 server | firewalld + fail2ban, unless your panel ships and supports CSF on EL10 | Avoids the deprecated iptables-nft and ipset path |
| VoIP/Asterisk server | fail2ban with Asterisk jails behind firewalld or nftables | Asterisk security logs map well to fail2ban filters (see fail2ban for Asterisk and FreePBX) |

If you are moving away from CSF, follow [Replace CSF with firewalld and fail2ban](/guides/replace-csf-with-firewalld-fail2ban/); if you are staying on cPanel, [migrating to the cPanel CSF fork](/guides/cpanel-csf-fork-migrate/) covers the switch. Port lists and rules for either side can be drafted with our [firewall rule builder](/tools/ai-firewall-rule-builder/).

**Official documentation:** [cPanel: CSF fork announcement](https://support.cpanel.net/hc/en-us/articles/37654028162071) · [fail2ban on GitHub](https://github.com/fail2ban/fail2ban) · [Plesk: Fail2Ban protection](https://docs.plesk.com/en-US/obsidian/administrator-guide/server-administration/plesk-for-linux-protection-against-brute-force-attacks-fail2ban.73381/) · [RHEL 10: deprecated features](https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/10.0_release_notes/deprecated-features)

**Related:** [CSF Fork 2026: Which Reliable Replacement After ConfigServer?](/guides/csf-fork-2026-after-configserver/) · [Replace CSF with firewalld and fail2ban: Secure Step-by-Step](/guides/replace-csf-with-firewalld-fail2ban/) · [CSF AlmaLinux 10: nftables and ipset Problems Fixed](/guides/csf-almalinux-10-nftables-ipset/) · [AI fail2ban Regex Generator: Filters and Jails from Log Lines](/tools/ai-fail2ban-regex-generator/) · [Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall](/guides/imunify360-without-csf/)

**See also:** [CSF Commands Cheat Sheet: Allow, Deny, Ports and Tempbans](/guides/csf-commands-cheat-sheet/) · [Replace CSF with firewalld and fail2ban: Secure Step-by-Step](/guides/replace-csf-with-firewalld-fail2ban/) · [Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall](/guides/imunify360-without-csf/)

## Frequently asked questions

### Is CSF still maintained in 2026?

The original ConfigServer project ended on 31 August 2025 and was released under the GPLv3. cPanel maintains a fixes-only fork called cpanel-csf, DirectAdmin maintains its own build, and other community forks exist. Run csf -v to see which one you have.

### Is fail2ban a firewall?

Not on its own. fail2ban reads logs and bans IPs through a firewall backend such as nftables, firewalld or iptables. Port rules and default policy still come from that firewall.

### Which uses fewer resources, CSF or fail2ban?

Memory is similar: about 35 MB for lfd and 33 MB for fail2ban-server on our labs. CPU depends on configuration, such as how many lfd checks are enabled or how much log data fail2ban parses.

### Can I use fail2ban on a cPanel server?

Yes. Install fail2ban-server rather than the full EPEL meta-package if CSF is the firewall, and use the csf ban action so CSF stays in charge of the rules. cPanel also has cPHulk for login protection.

### Does CSF support nftables?

CSF uses iptables commands, which on AlmaLinux 9 run on nftables through the iptables-nft layer. It has no native nftables backend, and Red Hat has deprecated iptables-nft and ipset, so test carefully on AlmaLinux 10.

### Does Plesk use CSF or fail2ban?

Plesk includes fail2ban as its “IP Address Banning (Fail2Ban)” component with preconfigured jails. The CSF readme does not list Plesk among its supported panels.
